{"ok":true,"contract":"shatteredcastles.ukc.model.v1","name":"Unified Kill Chain","version":"Pols-2017-final","suite":"ShatteredCastle(s)","source":{"author":"Paul Pols","date":"2017-12-07","artifact":"The Unified Kill Chain thesis","appendix":"Appendix A / Table 28"},"phases":[{"id":"reconnaissance","label":"Reconnaissance","definition":"Research, identify, and select targets using active or passive reconnaissance.","macro":"initial_foothold","canonical_order":1,"mandatory":false},{"id":"weaponization","label":"Weaponization","definition":"Prepare infrastructure and other resources required for the attack.","macro":"initial_foothold","canonical_order":2,"mandatory":false},{"id":"delivery","label":"Delivery","definition":"Transmit a weaponized object to the targeted environment.","macro":"initial_foothold","canonical_order":3,"mandatory":false},{"id":"social_engineering","label":"Social Engineering","definition":"Manipulate people into performing unsafe actions.","macro":"initial_foothold","canonical_order":4,"mandatory":false},{"id":"exploitation","label":"Exploitation","definition":"Exploit vulnerabilities or exposed features in systems.","macro":"initial_foothold","canonical_order":5,"mandatory":false},{"id":"persistence","label":"Persistence","definition":"Establish access, actions, or changes that maintain a presence on a system.","macro":"initial_foothold","canonical_order":6,"mandatory":false},{"id":"defense_evasion","label":"Defense Evasion","definition":"Specifically evade detection or avoid other defenses.","macro":"initial_foothold","canonical_order":7,"mandatory":false},{"id":"command_and_control","label":"Command & Control","definition":"Communicate with systems already under attacker control.","macro":"initial_foothold","canonical_order":8,"mandatory":false},{"id":"pivoting","label":"Pivoting","definition":"Tunnel through a controlled system toward systems that are not directly accessible.","macro":"pivot","canonical_order":9,"mandatory":false},{"id":"discovery","label":"Discovery","definition":"Gain knowledge about a system and its network environment.","macro":"network_propagation","canonical_order":10,"mandatory":false},{"id":"privilege_escalation","label":"Privilege Escalation","definition":"Obtain higher permissions on a system or network.","macro":"network_propagation","canonical_order":11,"mandatory":false},{"id":"execution","label":"Execution","definition":"Execute attacker-controlled code on a local or remote system.","macro":"network_propagation","canonical_order":12,"mandatory":false},{"id":"credential_access","label":"Credential Access","definition":"Obtain or control system, service, or domain credentials.","macro":"network_propagation","canonical_order":13,"mandatory":false},{"id":"lateral_movement","label":"Lateral Movement","definition":"Horizontally access and control other remote systems.","macro":"network_propagation","canonical_order":14,"mandatory":false},{"id":"collection","label":"Collection","definition":"Identify and gather information before exfiltration.","macro":"action_on_objectives","canonical_order":15,"mandatory":false},{"id":"exfiltration","label":"Exfiltration","definition":"Remove or aid removal of files and information from the target.","macro":"action_on_objectives","canonical_order":16,"mandatory":false},{"id":"target_manipulation","label":"Target Manipulation","definition":"Manipulate a target system to achieve an attack objective.","macro":"action_on_objectives","canonical_order":17,"mandatory":false},{"id":"objectives","label":"Objectives","definition":"Represent socio-technical objectives intended to achieve a strategic goal.","macro":"objectives","canonical_order":18,"mandatory":false}],"macros":[{"id":"initial_foothold","label":"Initial Foothold","phase_ids":["reconnaissance","weaponization","delivery","social_engineering","exploitation","persistence","defense_evasion","command_and_control"],"repeatable":true},{"id":"pivot","label":"Pivot / Choke Point","phase_ids":["pivoting"],"repeatable":true,"chokepoint":true},{"id":"network_propagation","label":"Network Propagation","phase_ids":["discovery","privilege_escalation","execution","credential_access","lateral_movement"],"repeatable":true},{"id":"action_on_objectives","label":"Action on Objectives","phase_ids":["collection","exfiltration","target_manipulation"],"repeatable":true},{"id":"objectives","label":"Objectives","phase_ids":["objectives"],"repeatable":false,"strategic":true}],"semantics":{"canonical_order_is_reference":true,"strict_sequence_required":false,"phases_may_be_bypassed":true,"phases_may_repeat":true,"out_of_order_occurrence_allowed":true,"branches_and_loops_allowed":true,"pivoting_is_chokepoint":true,"objectives_are_socio_technical":true,"free_text_auto_classification":false},"defensive_course_sets":{"information_operations":["detect","deny","disrupt","degrade","deceive","destroy"],"nist_csf_2014":["know","prevent","detect","respond","recover"]},"compatibility":{"mitre_attack_mapping":"not bundled; UKC phase vocabulary is preserved as the 2017 Pols model"},"model_digest_sha256":"01c5e53f11f40e13dc0ef1b9f4ebcb7acdeae284ef6f4d7e0b51a599c2488966","actions":["model","analyze_path","coverage","compare_paths"]}